A new nationwide survey suggests that most Americans are now likely to encounter scam attempts and cyberattacks.
In the poll, 91% of adults said they had experienced at least one, and 17% said they had lost money, according to Consumer Reports.
At the same time, trust in data privacy is moving in the opposite direction — Consumer Reports reported that only 32% of Americans were at least somewhat confident that sensitive personal information stayed private, down from 48% in May 2025.
Here's what to know
Consumer Reports, Aspen Digital, and the Global Cyber Alliance released the fifth annual Consumer Cyber Readiness Report for Cybersecurity Awareness Month.
Conducted in March and April, it draws on nationally representative surveys of 4,682 U.S. adults and 2,082 adults surveyed in May.
The report found that one in five consumers who had encountered a scam attempt said the most recent one had been tailored using their own details.
Phone-based scams stood out in particular. Among people whose most recent scam began with a call, 32% said it had been customized to them. The findings also suggest frustration over who should be responsible for stopping the problem.
Platform owners, such as social media, messaging, and sales platforms, were cited most often at 29%, followed by the federal government at 18%, individual consumers at 16%, and financial companies at 14%.
Consumer Reports President and CEO Phil Radford commented on the findings and the risk introduced as AI makes scams easier than ever to perpetrate.
"Nine in ten Americans have been targeted by a scam or cyberattack. That's not a statistic, that's almost everyone we serve," he began.
"AI is making fraud faster, cheaper, and more personal, and no one can out-smart that alone. Companies need to be held accountable. Governments need real guardrails. That's the bar we're setting — for ourselves and for them."
More background
While 17% of Americans reported losing money to a digital scam or cyberattack, Consumer Reports said only 7% recovered their losses.
Recovery also varied widely by payment method: 61% of people who used credit cards were reimbursed, compared with 45% for debit cards, 15% for peer-to-peer services, and 5% for cryptocurrency.
Many consumers, however, are already taking defensive steps.
In the March and April survey, 69% said they check links in texts and emails before clicking, 60% reported using multi-factor authentication, 48% said automatic software updates were turned on, and 44% said they use strong passwords.
What's being done?
The organizations behind the report pointed to a mix of personal and systemic responses.
One example is Take9, an initiative backed by Craig Newmark Philanthropies that urges people to pause for nine seconds before clicking, downloading, or sharing something online.
Businesses should offer multi-factor authentication and promote stronger password practices.
The report also contends that social media companies need to take more responsibility for scammers and make fraud reporting easier, including by providing access to a real person when problems arise.
On the policy side, the report points to measures such as the bipartisan SCAM Act and New York's False Social Media Advertising Prevention Act as ways to hold platforms more accountable.
It also notes that the Federal Trade Commission and state attorneys general could enforce current unfair and deceptive practices laws.
Aspen Digital acting Executive Director Konstanze Frischen put the survey's results in perspective.
"When nearly every American is being targeted online, the status quo on frauds and scams prevention is clearly broken. This year's report shows that consumers are fighting back, but they shouldn't have to fight alone," Frischen said.
"We need solutions that span across industry, civil society, philanthropy, and government to stop these attacks from continuing to hurt communities across the country."
Where can I learn more?
The survey's findings line up with a broader wave of AI-driven scams and data-use disputes. These stories cover Google's lawsuit over an alleged scam network, a devastating fraud case in Massachusetts, a fake CAPTCHA password trap, and broader fights over surveillance pricing.
• Google says an alleged AI scam ring spread across 9,000 sites and 1 million domains.
• In Massachusetts, American-made AI fueled a global scam that cost one man $400,000.
• Hackers are using fake CAPTCHA prompts to steal passwords, accounts, and crypto.
• Pennsylvania lawmakers are pushing a ban on surveillance pricing as data privacy worries grow.
Get TCD's free newsletters for easy tips, smart advice, and a chance to earn $5,000 toward home upgrades. To see more stories like this one, change your Google preferences here.







